<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://cooey.wiki/index.php?action=history&amp;feed=atom&amp;title=DFARS</id>
	<title>DFARS - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://cooey.wiki/index.php?action=history&amp;feed=atom&amp;title=DFARS"/>
	<link rel="alternate" type="text/html" href="https://cooey.wiki/index.php?title=DFARS&amp;action=history"/>
	<updated>2026-05-01T08:36:10Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.42.3</generator>
	<entry>
		<id>https://cooey.wiki/index.php?title=DFARS&amp;diff=21&amp;oldid=prev</id>
		<title>Marieramsay at 22:55, 26 September 2024</title>
		<link rel="alternate" type="text/html" href="https://cooey.wiki/index.php?title=DFARS&amp;diff=21&amp;oldid=prev"/>
		<updated>2024-09-26T22:55:27Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 22:55, 26 September 2024&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Several Defense Federal Acquisition Regulation Supplement (DFARS) clauses are directly related to CMMC (Cybersecurity Maturity Model Certification) and the protection of Controlled Unclassified Information (CUI).&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Several &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[https://www.acquisition.gov/dfars &lt;/ins&gt;Defense Federal Acquisition Regulation Supplement&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;] &lt;/ins&gt;(DFARS) clauses are directly related to CMMC (Cybersecurity Maturity Model Certification) and the protection of Controlled Unclassified Information (CUI).&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;These DFARS clauses mandate that contractors meet certain cybersecurity requirements and, in some cases, obtain CMMC certification. Here are the most relevant DFARS clauses:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;These DFARS clauses mandate that contractors meet certain cybersecurity requirements and, in some cases, obtain CMMC certification. Here are the most relevant DFARS clauses:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key cooey_mediawiki-mw_:diff:1.41:old-20:rev-21:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>Marieramsay</name></author>
	</entry>
	<entry>
		<id>https://cooey.wiki/index.php?title=DFARS&amp;diff=20&amp;oldid=prev</id>
		<title>Marieramsay at 22:54, 26 September 2024</title>
		<link rel="alternate" type="text/html" href="https://cooey.wiki/index.php?title=DFARS&amp;diff=20&amp;oldid=prev"/>
		<updated>2024-09-26T22:54:52Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 22:54, 26 September 2024&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l3&quot;&gt;Line 3:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 3:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;These DFARS clauses mandate that contractors meet certain cybersecurity requirements and, in some cases, obtain CMMC certification. Here are the most relevant DFARS clauses:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;These DFARS clauses mandate that contractors meet certain cybersecurity requirements and, in some cases, obtain CMMC certification. Here are the most relevant DFARS clauses:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;1. [https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting. DFARS 252.204-7012 – Safeguarding Covered Defense Information and Cyber Incident Reporting&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;]&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;1. [https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting. DFARS 252.204-7012&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;] &lt;/ins&gt;– Safeguarding Covered Defense Information and Cyber Incident Reporting&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This clause requires defense contractors to provide &amp;quot;adequate security&amp;quot; for covered defense information (CDI), including CUI, by implementing NIST SP 800-171 security requirements.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This clause requires defense contractors to provide &amp;quot;adequate security&amp;quot; for covered defense information (CDI), including CUI, by implementing NIST SP 800-171 security requirements.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Marieramsay</name></author>
	</entry>
	<entry>
		<id>https://cooey.wiki/index.php?title=DFARS&amp;diff=19&amp;oldid=prev</id>
		<title>Marieramsay: Created page with &quot;Several Defense Federal Acquisition Regulation Supplement (DFARS) clauses are directly related to CMMC (Cybersecurity Maturity Model Certification) and the protection of Controlled Unclassified Information (CUI).  These DFARS clauses mandate that contractors meet certain cybersecurity requirements and, in some cases, obtain CMMC certification. Here are the most relevant DFARS clauses:  1. [https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-inform...&quot;</title>
		<link rel="alternate" type="text/html" href="https://cooey.wiki/index.php?title=DFARS&amp;diff=19&amp;oldid=prev"/>
		<updated>2024-09-26T22:54:40Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;Several Defense Federal Acquisition Regulation Supplement (DFARS) clauses are directly related to CMMC (Cybersecurity Maturity Model Certification) and the protection of Controlled Unclassified Information (CUI).  These DFARS clauses mandate that contractors meet certain cybersecurity requirements and, in some cases, obtain CMMC certification. Here are the most relevant DFARS clauses:  1. [https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-inform...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Several Defense Federal Acquisition Regulation Supplement (DFARS) clauses are directly related to CMMC (Cybersecurity Maturity Model Certification) and the protection of Controlled Unclassified Information (CUI).&lt;br /&gt;
&lt;br /&gt;
These DFARS clauses mandate that contractors meet certain cybersecurity requirements and, in some cases, obtain CMMC certification. Here are the most relevant DFARS clauses:&lt;br /&gt;
&lt;br /&gt;
1. [https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting. DFARS 252.204-7012 – Safeguarding Covered Defense Information and Cyber Incident Reporting]&lt;br /&gt;
&lt;br /&gt;
This clause requires defense contractors to provide &amp;quot;adequate security&amp;quot; for covered defense information (CDI), including CUI, by implementing NIST SP 800-171 security requirements.&lt;br /&gt;
&lt;br /&gt;
It also mandates that contractors report cyber incidents to the DoD and includes the requirement to flow these obligations down to subcontractors handling CDI.&lt;br /&gt;
&lt;br /&gt;
While this clause does not explicitly require CMMC, compliance with NIST SP 800-171 forms the foundation for CMMC Level 2.&lt;br /&gt;
&lt;br /&gt;
2. [https://www.acquisition.gov/dfars/252.204-7019-notice-nistsp-800-171-dod-assessment-requirements. DFARS 252.204-7019] – Notice of NIST SP 800-171 DoD Assessment Requirements&lt;br /&gt;
&lt;br /&gt;
This clause mandates that contractors conduct a self-assessment against the 110 security requirements of NIST SP 800-171, scoring their compliance and uploading the results to the Supplier Performance Risk System ([[SPRS]]).&lt;br /&gt;
&lt;br /&gt;
Contractors must conduct this self-assessment as a prerequisite for contract awards, and the results are used in part to assess the contractor&amp;#039;s cybersecurity readiness, which ties into CMMC certification.&lt;br /&gt;
&lt;br /&gt;
3. [https://www.acquisition.gov/dfars/252.204-7020-nist-sp-800-171dod-assessment-requirements. DFARS 252.204-7020] – NIST SP 800-171 DoD Assessment Requirements&lt;br /&gt;
&lt;br /&gt;
This clause requires that the DoD or its authorized third-party assessors conduct assessments of the contractor’s compliance with NIST SP 800-171. This assessment could be a Basic, Medium, or High level, depending on the nature of the contract.&lt;br /&gt;
&lt;br /&gt;
This clause is a step towards ensuring contractors meet the requirements of CMMC Level 2, which is built on NIST SP 800-171 Rev 2.&lt;br /&gt;
&lt;br /&gt;
4. [https://www.ecfr.gov/current/title-48/chapter-2/subchapter-H/part-252/subpart-252.2/section-252.204-7021 DFARS 252.204-7021] – CMMC Requirements&lt;br /&gt;
&lt;br /&gt;
This clause is specific to CMMC and requires that defense contractors achieve the appropriate CMMC certification level for the contract they are bidding on.&lt;br /&gt;
&lt;br /&gt;
The CMMC level required will depend on the type of information handled (e.g., FCI or CUI). Certification must be verified by a CMMC Third-Party Assessment Organization (C3PAO) before contract award.&lt;br /&gt;
&lt;br /&gt;
This clause also requires that CMMC compliance flow down to any subcontractors involved in the contract who handle CUI or FCI.&lt;br /&gt;
&lt;br /&gt;
These DFARS clauses establish the foundation for cybersecurity compliance, with DFARS 252.204-7021 being the core clause specific to CMMC certification requirements.&lt;/div&gt;</summary>
		<author><name>Marieramsay</name></author>
	</entry>
</feed>